๐ฉ๐ช
Gwyneth Llewelyn
2026-09-21 20:38:25
(15 minutes ago)
2026/09/21 21:38:19 [error] 325891#325891: *1126449 access forbidden by rule, client: 34.170.207.215 ...
show more
2026/09/21 21:38:19 [error] 325891#325891: *1126449 access forbidden by rule, client: 34.170.207.215, server: gwynethllewelyn.net, request: "GET /portal/.env HTTP/2.0", host: "gwynethllewelyn.net"
2026/09/21 21:38:22 [error] 325888#325888: *1126483 access forbidden by rule, client: 34.170.207.215, server: gwynethllewelyn.net, request: "GET /workspace/.env HTTP/2.0", host: "gwynethllewelyn.net"
2026/09/21 21:38:23 [error] 325888#325888: *1126485 access forbidden by rule, client: 34.170.207.215, server: gwynethllewelyn.net, request: "GET /deploy/.env HTTP/2.0", host: "gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
jasperedv.de
2026-09-21 20:09:13
(45 minutes ago)
Apache Login - Brutforcing
Web App Attack
Brute-Force
๐บ๐ธ
Charlesiv
2026-09-21 20:05:27
(48 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /static//home/user/.env
Timestamp: 2026-09-21T15:35:01Z
Ray ID: a3ea2327accce802
UA: Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)
show less
Bad Web Bot
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-21 17:40:45
(3 hours ago)
2026/09/21 18:40:42 [error] 325888#325888: *1081552 access forbidden by rule, client: 34.170.207.215 ...
show more
2026/09/21 18:40:42 [error] 325888#325888: *1081552 access forbidden by rule, client: 34.170.207.215, server: [redacted], request: "GET /app/.env HTTP/2.0", host: "smtp.gwynethllewelyn.net"
2026/09/21 18:40:42 [error] 325888#325888: *1081547 access forbidden by rule, client: 34.170.207.215, server: [redacted], request: "GET /apps/.env HTTP/2.0", host: "smtp.gwynethllewelyn.net"
2026/09/21 18:40:42 [error] 325888#325888: *1081557 access forbidden by rule, client: 34.170.207.215, server: [redacted], request: "GET /web/.env HTTP/2.0", host: "smtp.gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-21 17:39:15
(3 hours ago)
This address swept through a list of pages that do not exist on our site within seconds โ a scanner ...
show more
This address swept through a list of pages that do not exist on our site within seconds โ a scanner working through its wordlist of exploitable paths. Blocked; please check the machine behind it for a scanner or malware. | method: GET (+1 more) | path: /config.json (+5 more) | 2026-09-21 17:39 UTC
show less
Port Scan
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-21 16:50:09
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ฎ
oh.mg
2026-09-21 15:30:40
(5 hours ago)
[Mon Sep 21 17:30:37.657288 2026] [security2:error] [pid 1592825:tid 1592835] [client 34.170.207.215 ...
show more
[Mon Sep 21 17:30:37.657288 2026] [security2:error] [pid 1592825:tid 1592835] [client 34.170.207.215:0] [client 34.170.207.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "hk.mmn.ca"] [uri "/"] [unique_id "arFNnbedD5Gz3Ck5buwWAAAAAQg"]
[Mon Sep 21 17:30:40.210804 2026] [security2:error] [pid 1592825:tid 1592838] [client 34.170.207.215:0] [client 34.170.207.215] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-ev
...
show less
Web App Attack
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-09-21 15:11:26
(5 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:04:58
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.207.215 (215.207.170.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.207.215 (215.207.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:04:52.194050 2026] [security2:error] [pid 25946:tid 25946] [client 34.170.207.215:38918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.aticom.net"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "arFHlE4Icr-VS3U_a0U2uQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-21 14:42:25
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
๐บ๐ธ
magnetosphere-tarpit
2026-09-21 14:24:13
(6 hours ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2026-09-21 14:17:16
(6 hours ago)
34.170.207.215 - - [21/Sep/2026:16:17:11 +0200] "GET /uw22tt4woksg1fekbb8p HTTP/1.1" 403 503 "-" "Mo ...
show more
34.170.207.215 - - [21/Sep/2026:16:17:11 +0200] "GET /uw22tt4woksg1fekbb8p HTTP/1.1" 403 503 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.170.207.215 - - [21/Sep/2026:16:17:13 +0200] "GET /backend/.env HTTP/1.1" 403 503 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.170.207.215 - - [21/Sep/2026:16:17:13 +0200] "GET /src/.env HTTP/1.1" 403 503 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.170.207.215 - - [21/Sep/2026:16:17:13 +0200] "GET /rclone.conf HTTP/1.1" 403 503 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.170.207.215 - - [21/Sep/2026:16:17:15 +0200] "GET /packages/.env HTTP/1.1" 403 503 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/sear
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:16:34
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.207.215 (215.207.170.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.207.215 (215.207.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:16:28.453634 2026] [security2:error] [pid 26250:tid 26289] [client 34.170.207.215:52200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.clmtic.net"] [uri "/@fs/app/.env"] [unique_id "arE8PBCBaSEmDeYab75kyAAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 14:11:49
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
valornode
2026-09-21 13:41:23
(7 hours ago)
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/thinkphp-cve-2018-20062 ...
show more
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/thinkphp-cve-2018-20062 | ASN: 396982 (GOOGLE-CLOUD-PLATFORM) | Country: US | Range: 34.160.0.0/12
show less
Brute-Force
SSH